ZeroHour
Security Affairspublished ()ingested @securityaffairs

Crooks exploit VMWare ESXi flaws to encrypt disks of VMs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-5544
Heap-Based Buffer Overflow in OpenSLP Used by VMware ESXi and Horizon DaaS

CVE-2019-5544 is a heap-based buffer overflow (CWE-787, heap overwrite) in the OpenSLP service shipped with VMware ESXi and the Horizon DaaS appliances, rated Critical at CVSSv3 9.8 by VMware. The flaw is reachable through the network-facing Service Location Protocol service with no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), so a remote attacker can trigger the heap overwrite with high confidentiality, integrity, and availability impact — in practice, remote code execution on the affected host. Organizations running affected ESXi builds or Horizon DaaS appliances are directly exposed, and CPE data also ties the flaw to upstream OpenSLP and Red Hat Enterprise Linux/Fedora packages that ship it. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use and EPSS puts its 30-day exploitation probability at 97.3%. Related reporting describes criminals exploiting VMware ESXi flaws to encrypt VM disks and a previously undetected ESXi backdoor, and no public PoC is catalogued.

Do: Apply updates per vendor instructions — the CISA KEV required action — for ESXi, Horizon DaaS, and any affected OpenSLP packages from Red Hat/Fedora. As an interim mitigation, restrict or disable the SLP service (TCP/UDP port 427) on ESXi hosts and avoid exposing management interfaces to the internet. Given known ransomware use since the 2021-11-03 KEV listing, hunt for signs of compromise on any unpatched ESXi hosts.

9.897% KEV ransomware
  • VMware ESXi
  • VMware Horizon DaaS (appliance)
  • OpenSLP (upstream)
  • +9 more
masshundreds of thousands to millions of ESXi hosts deployed; tens of thousands internet-exposed with the SLP service (port 427) reachable
CVE-2020-3992
Use-After-Free RCE in VMware ESXi OpenSLP Service (Port 427)

CVE-2020-3992 is a use-after-free (CWE-416) in the OpenSLP service used by VMware ESXi, rated critical at CVSS 9.8. An unauthenticated attacker with access to port 427 on an ESXi host's management network can send crafted SLP traffic that triggers the memory-reuse flaw and gains remote code execution on the hypervisor. Successful exploitation grants full control of the ESXi host, and attackers have used these OpenSLP flaws in the ESXiArgs ransomware campaign to encrypt the disks of hosted virtual machines. Affected products are ESXi 7.0, 6.7 and 6.5 prior to the October 2020 patch releases (as well as the related VMware Cloud Foundation). The flaw is in CISA's KEV catalog (added 2021-11-03) with ransomware use confirmed, and EPSS assigns an 83% probability of exploitation within 30 days (100th percentile); no public PoC is listed in the source data.

Do: Apply VMware's ESXi security patches: ESXi_7.0.1-0.0.16850804 (7.0), ESXi670-202010401-SG (6.7), or ESXi650-202010401-SG (6.5), or the corresponding VMware Cloud Foundation update, per CISA's required action. As interim mitigation, restrict or disable the SLP service and firewall port 427 so ESXi management interfaces are not reachable from the internet. Because ransomware use is confirmed, check hosts for signs of compromise; CISA has published an ESXiArgs recovery script for affected deployments.

9.883% KEV ransomware
  • vmware ESXi 7.0 before ESXi_7.0.1-0.0.16850804
  • vmware ESXi 6.7 before ESXi670-202010401-SG
  • vmware ESXi 6.5 before ESXi650-202010401-SG
  • +1 more
large≈90,000-100,000 internet-exposed ESXi hosts on port 427 (many more reachable only on internal management networks)
Full article300 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 02, 2021

Ransomware operators are exploiting two VMWare ESXi vulnerabilities, CVE-2019-5544 and CVE-2020-3992, to encrypt virtual hard disks.

Security experts are warning of ransomware attacks exploiting two VMWare ESXi vulnerabilities, CVE-2019-5544 and CVE-2020-3992, to encrypt virtual hard disks.

According to ZDNet, threat actors are using VMWare ESXi exploits to encrypt the disks of virtual machines deployed in enterprise environments.

Since October, the RansomExx Ransomware gang (also known as Defray777) expanded its operations by targeting VMWare virtual machines.

Victims reported that their VMs were abruptly shut down and then all files on the datastore were encrypted (vmdk, vmx, logs). Threat actors left the ransom note at the datastore level.

The news of the attack was also confirmed by the popular cybersecurity researchers Kevin Beaumont that reported that threat actors are using the two issues to bypass all Windows OS security, by shutting down VMs and encrypting the VMDK’s directly on hypervisor.

https://twitter.com/GossiTheDog/status/1324896051128635392

Both CVE-2019-5544 and CVE-2020-3992 vulnerabilities in VMware ESXi impact the Service Location Protocol (SLP), reside in the OpenSLP open-source implementation of the Service Location Protocol (SLP), which allows the software to locate resources on a network.

The CrowdStrike experts, Sergei Frankoff and Eric Loui, also reported that the Sprite Spider ransomware operators also started targeting ESXi hosts since July 2020. 

ZDNet reported that at the time of this writing only RansomExx ransomware operators are exploiting the above issues, but it is aware that the operators of the Babuk Locker ransomware will implement a similar attack chain.

System administrators are recommended to update their VMWare ESXi installs or disable SLP support to secure them.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, VMWare ESXi)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/114124/malware/ransomware-attack-vmware-esxi.html